CVE-2021-29487
Authentication bypass in Octobercms
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can exploit this vulnerability to bypass authentication and takeover of and user account on an October CMS server. The vulnerability is exploitable by unauthenticated users via a specially crafted request. This only affects frontend users and the attacker must obtain a Laravel secret key for cookie encryption and signing in order to exploit this vulnerability. The issue has been patched in Build 472 and v1.1.5.
octobercms en una plataforma CMS basada en el framework PHP Laravel. En las versiones afectadas del paquete october/system un atacante puede explotar esta vulnerabilidad para omitir la autenticación y hacerse con una cuenta de usuario en un servidor de October CMS. La vulnerabilidad puede ser explotada por usuarios no autenticados por medio de una petición especialmente diseñada. Esto sólo afecta a usuarios del frontend y el atacante debe obtener una clave secreta de Laravel para el cifrado y la firma de cookies con el fin de explotar esta vulnerabilidad. El problema ha sido parcheado en el Build 472 y en la versión v1.1.5.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-03-30 CVE Reserved
- 2021-08-26 CVE Published
- 2024-05-11 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-287: Improper Authentication
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Octobercms Search vendor "Octobercms" | October Search vendor "Octobercms" for product "October" | >= 1.0.471 < 1.0.472 Search vendor "Octobercms" for product "October" and version " >= 1.0.471 < 1.0.472" | - |
Affected
| ||||||
Octobercms Search vendor "Octobercms" | October Search vendor "Octobercms" for product "October" | >= 1.1.1 < 1.1.5 Search vendor "Octobercms" for product "October" and version " >= 1.1.1 < 1.1.5" | - |
Affected
|